Impact
The Wbcom Designs lock‑my‑bp plugin contains a missing authorization flaw that permits users to use the plugin’s features without proper authentication, potentially allowing reading, modification, or insertion of data on the WordPress site. The weakness is identified as CWE-862, a broken access control vulnerability.
Affected Systems
This vulnerability affects the Wbcom Designs lock‑my‑bp WordPress plugin through version 2.1.1. The affected vendor is Wbcom Designs and the product is the lock‑my‑bp plugin for WordPress.
Risk and Exploitability
The vulnerability scores a CVSS of 5.3, indicating moderate severity. The EPSS is < 1%, suggesting low exploitation probability, and it is not listed in the CISA KEV catalog. The likely attack vector is web‑based; an attacker would need to access the WordPress admin interface or have a user account with elevated privileges to craft requests that bypass the plugin’s authorization checks and gain unauthorized access to administrative functions.
OpenCVE Enrichment